CRITICAL🇵🇱 Wersja polska

CVE-2024-45169

CVSS 9.8v3.1pub. 2024-08-22upd. 2025-09-04

An issue was discovered in UCI IDOL 2 (aka uciIDOL or IDOL2) through 2.12. Due to improper input validation, improper deserialization, and improper restriction of operations within the bounds of a memory buffer, IDOL2 is vulnerable to Denial-of-Service (DoS) attacks and possibly remote code execution via the \xB0\x00\x3c byte sequence.

🤖 AI Analysis
How it works

An attacker can send a specially crafted byte sequence (\xB0\x00\x3C) to the vulnerable system, which is not properly validated by the application. Improper deserialization of input data combined with lack of buffer memory boundary control (CWE-119) leads to its overflow or corruption of the application's internal state. The attack vector is the network, requires no authentication or user interaction, which significantly lowers the threshold for its exploitation.

Impact

An attacker can cause permanent service unavailability (DoS) or — in the worst scenario — achieve remote execution of arbitrary code (RCE) on the server or client workstation with IDOL2 process privileges, which may result in complete system compromise.

Mitigation & patch

Patches available from the vendor should be applied according to references. It is recommended to monitor the vendor's website (uci.de) for an updated IDOL2 client version and restrict network access to the service only to trusted hosts until the patch is deployed.

Who is affected

UCI IDOL 2 (also known as uciIDOL or IDOL2) in all versions up to and including 2.12

Analysis generated by Claude AI (Anthropic) based on NVD data. Always verify with vendor.
CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
  • Uci Idol2

    APP
    Uci
    ≤ 2.12
🔵
CHECK WITH VENDOR
No clear patch data available. Check vendor references.
Tags
RCEDeserialization
CWE
References

Related vulnerabilities

CVE-2024-45166CRITICAL9.8PL ✓same product

RCE i DoS w UCI IDOL 2 przez błędną deserializację i przepełnienie bufora

CVE-2024-45167CRITICAL9.8PL ✓same product

RCE i DoS w UCI IDOL 2 przez improper input validation i deserializację

CVE-2024-45168CRITICAL9.1PL ✓same product

UCI IDOL 2: brak uwierzytelnienia w komunikacji przez raw socket

CVE-2024-45165MEDIUM5.3same product

An issue was discovered in UCI IDOL 2 (aka uciIDOL or IDOL2) through 2.12. Data is sent between client and ser...